Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
review · Q2 2026 DeFi Record Hack Wave
- Sequence
- #2
- Score
- 0 → 0 (0)
- Cluster
- mainnet-beta
- Slot
- 443517556
- Off-chain at
- 2026-08-25T22:21:45.121Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 9Y3KvcbQYEozFcbuT2KNFKSZEZjpQEXz6oGyYCRQFkT1
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (1372 chars)
{"actor":"reviewer","decided_at":"2026-08-25T22:21:45.040Z","decision":"review","investigation_id":"0180d047-73a2-45da-9503-dfef6cc4ea9d","new_score":0,"page_slug":"q2-2026-defi-record-hack-wave","prev_score":0,"reason":"The large majority of atomic claims on this page — including the technical mechanics of the KelpDAO, Drift, Humanity Protocol, and THORChain exploits and their North Korea attributions — were independently verified against primary sources (Chainalysis, TRM Labs, LayerZero, THORChain's own reports) and found accurate. However, four claims are disputed: a fabricated-looking quote attributed to altfins/thirdweb, a governance-migration date conflated with the attack date, a misattributed $14B DeFi-withdrawal figure (credited to CoinTribune when the actual source is ECIKS/Financial Times), and a $1.3M 'second Aztec Connect exploit' figure that actually belongs to the separately-listed Raydium incident. The page's headline incident-count and loss-total figures (83 incidents/$755M) are also less settled than presented, given credible contemporaneous sources — including one already in the page's own source pool — reporting materially different totals (70-85 incidents, $746M-$775M) for the same quarter.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}